
php_filter_chain_generator
CLI to generate PHP filter chains for remote code execution via controlled include/require parameters. Produces complex iconv-based filter bypasses…

CLI to generate PHP filter chains for remote code execution via controlled include/require parameters. Produces complex iconv-based filter bypasses…

Mousejack for ATmega32u4

weaponized tool for CVE-2020-17144

Struts2 S2-045(CVE-2017-5638)Exp with GUI

Kautilya - Tool for easy use of Human Interface Devices for offensive security and penetration testing.

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Mousejack for Arduino UNO

Polymorphic C2 framework with graphical interface, automatic reconnection, payload generation, and integrated hacking tools for red team operations…

Tools for investigating Log4j CVE-2021-44228

CLI wrapper for MSFvenom that streamlines payload creation with profile management, automated listener generation, and organized output for…

Proof-of-concept exploit for CVE-2019-3980 enabling remote command execution via custom C# payload with HTTP callback for output retrieval.

Public PoC for CVE-2025-25257: FortiWeb pre-auth SQLi to RCE

Quick test environment for CVE-2021-44228 Log4j RCE vulnerability with a built-in exploit server and customizable payload execution.

PoC exploit for CVE-2021-33026 that poisons Redis cache in Flask-Cache to achieve remote code execution via malicious pickle deserialization.

A PoC for CVE-2025-24813

Exploit for CVE-2025-53770, a SharePoint ViewState deserialization vulnerability, enabling remote code execution via crafted payloads.

Proof-of-concept exploit for CVE-2020-11932, a double-free vulnerability in WhatsApp GIF processing, enabling remote code execution via crafted .gif…

Python exploit for Drupal 8 core RESTful API RCE (CVE-2019-6340) that sends crafted requests to execute arbitrary commands on vulnerable sites.